CVE-2024-11053
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Centos, Debian, Ibm Aix, Linuxmint, Mysql Server
- Haxx Curl
- < 8.11.1
- Fix
- Available
- CVSS 3.1
- 3.4 LOW
- EPSS
- 1.4% (69th percentile)
- NVD status
- Modified
- Published
- 2024-12-11
CVE-2024-11053 at NVD
No indexed exploits for CVE-2024-11053 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-11053 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.